What this service stores, for how long, and who can see it.
Each workspace belongs to a customer — a company or an individual. They decide what their assistant knows and what it is used for. This platform runs it on their behalf and does not decide what their assistant is for. If you are an end user who messaged a company's assistant, that company holds your relationship; we hold the machine.
| Data | Why | Kept for |
|---|---|---|
| Documents a customer uploads | To answer from them | Until the customer deletes them |
| Questions asked, with their answers | So a repeated question is not recomputed | 30 days |
| Questions the assistant could not answer | So the customer can fill the gap | 90 days |
| Questions asked (text), deduplicated with a counter | So the customer can see what their public needs | 90 days |
| Daily question counts per channel — no text, no sender | A trend line on the customer's dashboard | 400 days |
| Account email and password hash | To sign in | Until the account is closed |
| A chat ID, for the workspace owner only | So only they can change what the bot knows | Until unlinked |
Your chat ID, if you sent /subscribe | So that one business can send you its news | Until you send /stop or /forget |
There is no profile, no message history, and no behavioural tracking.
Promotional messages exist, but only one way: a business can send news to
people who explicitly subscribed by sending
/subscribe to its assistant. Nothing about what you asked is used
for targeting, subscriber lists are never shared between businesses or sold,
and /stop ends it — one word, immediately, no questions.
Your documents are stored, indexed and searched entirely on a single machine in Bangkok. Search itself never leaves that machine: the corpus is never uploaded anywhere.
Writing the final answer works one of two ways, set per workspace:
A workspace owner chooses the mode and can switch at any time. If you want to know which mode a particular assistant uses, ask its owner or write to us.
No other third party receives message content.
/privacy for this notice or
/forget to erase what is stored about you, immediately./subscribe opts in to one business's news; /stop
opts out. Neither affects your ability to ask questions.Traffic is encrypted in transit. Access to a workspace requires a signed-in account that owns it, and cross-workspace reads are refused. Bot webhooks are verified — Telegram by a secret token, LINE by signature — so a stranger cannot drive someone's assistant.
Stored files are held on a local drive that is not encrypted at rest. If that matters for your material, do not upload it until we tell you that has changed.
This service is for businesses and is not directed at children.